client-reverse
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading JavaScript bundles from external domains using
wgetto facilitate offline analysis and secret hunting. - [COMMAND_EXECUTION]: Includes shell commands such as
wgetandgrepfor reconnaissance purposes, specifically for identifying cryptographic secrets and signature logic in captured files. - [REMOTE_CODE_EXECUTION]: Provides Python script templates that use the
requestslibrary to automate API interactions. These scripts are intended for replaying signed requests and performing security testing (fuzzing) on target endpoints. - [DATA_EXPOSURE]: The skill documents methods for locating and extracting hardcoded credentials (like HMAC secrets) from client-side code. This is presented as a security auditing technique rather than a malicious activity.
Audit Metadata